Scope & Quantitative Fiduciary Duty
Nova Spectrum Pro Inc., operating alongside its international branches, execution conduits, and sovereign capital vehicles (collectively, "Nova Spectrum Pro", "the Platform", "we", or "us"), treats data privacy as an uncompromisable fiduciary duty. Our systematic trading engine, machine learning portfolio models, and institutional prime interfaces operate under high-entropy security mandates.
This Policy governs the processing of data collected across
all Nova Spectrum Pro execution terminals, Client Portals,
algorithmic API bridges (FIX 4.4 / REST / WebSocket telemetry), institutional consultation desks, and institutional
investor onboarding channels.
Nova Spectrum Pro will NEVER sell, lease, syndicate, license, or barter your personal records, trading telemetry, asset valuations, order routing vectors, or proprietary alpha configurations to data brokers, high-frequency predatory desks, or marketing aggregates.
Categories of Information Collected
In delivering ultra-low-latency quant routing, algorithmic rebalancing, and compliant custodial clearance, we gather distinct data classes strictly proportionate to regulatory necessity and execution performance:
- Government-issued biometric passports and national IDs
- Corporate Articles, Certificate of Incumbency, and LEI codes
- Ultimate Beneficial Ownership (UBO) declarations (>10% equity)
- Proof of physical sovereign tax domicile
- Tier-1 Prime Broker routing coordinates and SWIFT BIC
- Qualified Purchaser & Accredited Investor verification
- Source of Wealth (SoW) and Source of Funds (SoF) proofs
- Risk tolerance profiles and volatility drawdown mandates
- FIX Protocol order messages, cancels, and executions
- Sub-millisecond connection latencies & packet timestamps
- API token authentications and IP whitelist binds
- Hardware MAC addresses and browser crypt-fingerprints
- Multi-Party Computation (MPC) partial share fingerprints
- Hardware Security Module (HSM) session authorizations
- Time-based One-Time Password (TOTP) seed rotation logs
- Deterministic public routing addresses
Purpose & Legal Basis of Processing
Under Article 6 of the General Data Protection Regulation (GDPR) and reciprocal global frameworks, each computational operation on client data rests upon explicit lawful foundations:
Continuous portfolio optimization, order routing, and rebalancing calculation.
OFAC, EU, UN, and DFSA screening, sanction checks, and STR filings.
Telemetry-driven firewall analytics, rate-limiting, and distributed credential defense.
Cryptographic Storage & Zero-Trust Protocol
Nova Spectrum Pro enforces a zero-trust, defense-in-depth posture across all computational nodes. Identity data, API keys, and financial credentials are cryptographically isolated from Internet-exposed execution nodes.
Transit Shield
TLS 1.3 / mTLS mandatory with Perfect Forward Secrecy (PFS)
Rest Encryption
AES-256-GCM cipher with customer-dedicated envelope encryption
MPC Sharding
Threshold Signature Schemes (TSS 2-of-3) eliminating single private keys
Internal engineers have no mechanical access to clear-text trading models, private cryptographic keys, or unmasked investor credentials. All administrative interactions require dual-custody authorization within hardware-fenced enclave compute modules.
Disclosure to Tier-1 Custodians & Authorities
We transmit strictly essential data payloads to authorized institutional counterparties for order clearing, settlement, and statutory governance:
| Entity Category | Data Shared | Jurisdictions | Safeguards |
|---|---|---|---|
| Tier-1 Custodian Banks | LEI, Account Numbers, Settlement Vectors | CH, UK, US, SG | Encrypted Direct Lease Line |
| Statutory Regulators (FINMA, FCA, SEC) | Audit Trails, Suspicious Activity Reports (STR) | Global Accord | Signed Diplomatic Relays |
| AML / Sanctions Screening Desks | Names, Date of Birth, Sovereign Tax IDs | EU / US | Tokenized Hash Matching |
| Low-Latency Optical Networks | Anonymized FIX execution signals | LD4, NY4, TY3 | Zero Identity Metadata |
International Data Transfers & Cross-Border Relays
Given our continuous 24/7 algorithmic routing across global financial exchanges (New York, London, Zurich, Tokyo, Dubai), client data may be processed outside your home nation.
Where cross-border transfers occur out of the European Economic Area (EEA), United Kingdom, or Switzerland, Nova Spectrum Pro implements:
- Standard Contractual Clauses (SCCs) ratified by the European Commission, supplemented by comprehensive Transfer Impact Assessments (TIAs).
- Sovereign Data Fencing: European client identity vaults are physically anchored within Tier-4 data vaults in Frankfurt and Zurich.
- UK International Data Transfer Addendum satisfying ICO specifications.
Global Client Data Rights (GDPR & CCPA SLA)
Institutional allocators, corporate signers, and private investors retain unalienable jurisdictional control over their sovereign data profile:
Purge of non-statutory records across all active compute instances upon account closure, subject to 5-year anti-money laundering statutory hold limits.
Direct export of trade histories, capital telemetry, and verification logs in machine-readable JSON or signed ISO 20022 XML formats.
Rapid remediation of corporate governance, beneficial ownership percentages, or updated financial disclosures via your dedicated desk.
Immediate cessation of optional performance analytics telemetry and quantitative model profiling.
Cookie Policy & Algorithmic Telemetry Controls
We reject intrusive third-party commercial pixels, social media ad scrapers, or affiliate tracers. Telemetry is gathered exclusively for security integrity, latency optimization, and terminal state persistence.
Strictly Necessary & Execution Session Tokens
Required for cryptographic authentication, FIX API sessions, and load balancing.
Sub-Millisecond Latency Diagnostics
Transmits anonymous network packet jitter statistics back to edge data centers.
Predictive Yield Interface Profiling
Caches localized dashboard views based on your past asset allocations.
Data Retention Schedules & Secure Shredding
Data is stored strictly for the duration necessary to satisfy quantitative fiduciary mandates and mandatory financial regulatory books-and-records periods:
• Statutory Financial Books (7 Years): Trade settlement tickets, capital receipts, SWIFT confirmation logs, and tax statements (pursuant to SEC Rule 17a-4 and Swiss CO Art. 958f).
• AML Identification Dossiers (5 Years post-termination): Stored in tamper-proof WORM (Write Once, Read Many) cloud-storage modules.
• Volatile Telemetry Records (90 Days): Micro-latency captures, IP logs, and unauthenticated packet inspection records are continuously shredded using cryptographic zeroization.
DPO Contact & Supervisory Authority Inquiries
Should you wish to file a formal subject access request, revoke consent, or question algorithmic data handling protocols, contact our lead Data Protection Officer directly:
EEA clients additionally maintain the unconditional legal prerogative to file an inquiry or grievance with their regional data protection authority (e.g., the Irish Data Protection Commission or the German Federal Commissioner for Data Protection and Freedom of Information BfDI).
